Monitoring Splunk

What does "./splunk stop" do?

nick405060
Motivator

My indexer takes a good 5+ minutes to stop, so I've been pkill -f'ing it for the last year and a half. What does ./splunk stop do, how is a straight process kill different, and what am I risking?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Don't kill Splunk. The splunk stop command tells Splunk to shut down gracefully. It waits for outstanding searches to complete before stopping. If you pull the rug out from under splunkd you risk corrupting your data in the event a lookup file is being written or a bucket is being updated.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...